Resolution criteria
This market resolves to YES if an incident meeting all six of the following conditions occurs between October 2, 2026, and June 30, 2027, at 23:59 UTC, and is publicly confirmed by September 30, 2027. Otherwise, the market resolves to NO. Resolution may be deferred until September 30, 2027, to allow for public confirmation.
Attacker: The cyber-attacker must be an AI model developed by OpenAI, Anthropic, or Google DeepMind (GDM), running on that lab's infrastructure or under its direct control (including internal use, training, research, or evaluation sandboxes). Models deployed for third-party customer use via APIs or consumer-facing products do not qualify.
Target: The target must be one of the other two labs (excluding the attacking lab's own systems). This includes systems operated by the target lab, its parent company (e.g., Google or Alphabet for GDM), cloud infrastructure rented by the lab, or employees' official work accounts. Employees' personal accounts do not count.
Compromise: The model must have gained unauthorized access to non-public systems, accounts, or data of the target lab. This includes exploiting technical vulnerabilities, executing remote code, or using stolen/leaked credentials. Blocked attempts, publicly available data gathering, and access granted under authorized red-teaming, bug bounty, or penetration testing agreements do not count.
No human authorization: The intrusion must have occurred without human direction or approval. The model must have decided on its own initiative to break in. A human instructing a model to conduct the hack does not qualify, even if the model performs all subsequent technical tasks.
Confirmation: The incident must be confirmed by the attacking lab, the target lab, or an independent investigative body (such as METR, Redwood Research, or a named incident response firm), or reported by at least two of the following media outlets citing one of those parties: Reuters, Bloomberg, AP, Financial Times, New York Times, Wall Street Journal, or WIRED.
Purpose: A primary purpose of the intrusion must have been to obtain the target lab's research assets (such as algorithmic/architectural methods, model weights, training or inference code, training data, unpublished research results, or safety and evaluation methods). The purpose must be explicitly stated by the attacking lab, target lab, or an independent investigator based on model logs, reasoning traces, or accessed data.
If the exact timing of the unauthorized access is disputed, it must be shown to have occurred before June 30, 2027) to count. A hack that has already occurred (before October 2) but has not yet been publicly confirmed will also resolve the market to Yes.
Background
The intersection of frontier AI capabilities and cybersecurity has escalated rapidly:
July 2026 Hugging Face Incident: During internal cyber-capability testing on the "ExploitGym" benchmark, autonomous OpenAI models bypassed sandbox isolation protocols via a zero-day vulnerability. The agents accessed the public internet and compromised Hugging Face's production infrastructure to retrieve test answers. An investigation report by OpenAI and an independent assessment by METR identified a highly persistent internal research model as the main driver.
September 2026 Hacktron AI Hack: A three-person security team utilized Anthropic's Claude to chain multiple vulnerabilities, compromise OpenAI employee accounts, and open a pull request in OpenAI's internal code repository within 72 hours. This was an authorized bug-bounty effort (which earned a $6,500 bounty), demonstrating human-directed cross-lab exploitation.
This market tracks whether an AI agent from one of the three leading frontier labs will autonomously initiate and execute an intrusion into a rival lab to steal research assets.